Security Guides
A licence number is still a key somewhere: what AssuranceAmerica customers should do after the 7 million-person breach
US auto insurer AssuranceAmerica disclosed a breach affecting about 7 million people, including driver's license numbers and some SSNs. What was taken, per the company's notice and state AG filings, and what to do today: credit freezes and contacting your state motor vehicle agency.
For: anyone who has had auto insurance with AssuranceAmerica in the US (policyholders, listed drivers, people involved in claims), and anyone who runs a service that stores identity numbers. This article is based on the company's official notice, state attorney general filings and guidance from US public agencies. It does not cover attack methods.
What affected people should do today
Use your notice to see exactly what was exposed about you
The company sent notices to potentially affected people and posted the notice on its website. What was exposed varies by individual, so first check whether your notice mentions a Social Security number or Tax ID. If it does, the credit freeze below is your top priority. Questions go to the toll-free line in the notice, 1-844-854-2353 (Monday to Friday, 9 a.m. to 9 p.m. Eastern).
California and Pennsylvania residents: enroll in monitoring by October 10
The company is offering residents of California and Pennsylvania a complimentary 12-month credit monitoring service. The enrollment deadline is October 10, 2026, and you enroll by contacting the company. The notice says enrolling will not hurt your credit score.
Place a credit freeze with all three bureaus
With a credit freeze in place, nobody can open a new credit account in your name. The FTC says placing and lifting a freeze is free and doesn't affect your credit score. You need to contact each of Equifax, Experian and TransUnion. You can lift it temporarily when you apply for credit yourself.
Pull your credit reports and look for accounts you don't recognize
Get your free reports from all three bureaus at annualcreditreport.com and look for cards, loans or inquiries you didn't initiate. The company's notice likewise asks people to review credit reports and bank and other financial statements, and to contact their financial institution immediately about anything suspicious.
Tell your state motor vehicle agency that your license number was exposed
The FTC's recovery guidance says that if your driver's license information was lost or stolen, contact your nearest motor vehicles branch. The state might flag your license number in case someone else tries to use it, or suggest that you apply for a duplicate. Find your state's agency through USA.gov's "State motor vehicle services" directory. The California DMV, for example, has a dedicated form (INV 35) for requesting a fraud review of your driver license record.
Verify anyone claiming to be your insurer or agent by calling back
The exposed data includes policy and claims details. A message saying "we need to verify your identity for your claim" or "you're owed a premium refund" looks convincing when it gets those details right. Don't use numbers or links in the message; call the number on your policy documents or insurance ID card (see what is phishing?).
If fraud actually happens: IdentityTheft.gov and the police
If you find accounts or charges you don't recognize, contact the fraud department of the business involved, and report it at the FTC's IdentityTheft.gov to get a recovery plan. The company's notice also points out that you have the right to file a police report, and that you can contact the FTC or your state attorney general.
SSN or Tax ID + name and address (some people)
↓→
New credit in your name
→ Credit freeze at all three bureaus / check reports
Driver's license number + name and address
↓→
Applications that ask for a license number (benefits, insurance)
→ Contact your state motor vehicle agency (flag / duplicate)
Policy and claims details + contact info
↓→
Convincing contact posing as your insurer
→ Call the number on your policy documents
What happened (from AssuranceAmerica's notice and state filings)
The following is taken from the company's official notice and filings published by the California and Indiana attorneys general.
March 16, 2026
The date of the malicious activity that targeted one of the company's employees, per the notice.March 17
The company detects suspicious activity on certain systems, starts investigating and engages external forensic specialists.During the investigation
It determines that an unauthorized third party accessed certain portions of its IT environment and copied certain data files.June 15
The review of the affected files (to identify whose information they contained) is completed.June 17
The date shown for the filing on the California Attorney General's breach list.July 10
The company posts its notice. The Indiana Attorney General's list also shows notices sent on July 10.October 10 (deadline)
Enrollment deadline for credit monitoring for California and Pennsylvania residents.
- Exposed (varies by person)
- Name, contact information, auto insurance policy or account information, driver or vehicle information, claims-related information, driver's license number
- Limited number of people
- Tax ID information or Social Security number
- Sequence
- Malicious activity targeting an employee on March 16. A third party accessed part of the IT environment and copied data files
- Company response
- Disabled compromised credentials, terminated unauthorized sessions, isolated affected systems, notified law enforcement. Reset passwords, deployed enhanced monitoring and threat detection tools, gave staff additional cybersecurity instruction
- Support
- Complimentary 12-month credit monitoring for California and Pennsylvania residents (enroll by October 10, 2026)
- Cause details
- Not disclosed beyond "malicious activity that targeted one of the Company's employees"
- Contact
- 1-844-854-2353 (Monday to Friday, 9 a.m. to 9 p.m. Eastern)
How to read it: the notice took about four months
Detection was March 17; the notice came July 10. The company says that, because of the nature of the files and the scope of the review, identifying whose information they contained took until June 15. So for roughly four months after detection, the people affected didn't know. Now that you have the notice, assume not "nothing has happened yet" but "this may have been in someone else's hands for months", and get the freeze and checks done first.
What can a US driver's license number be used for?
In the US, a driver's license is the everyday ID, and its number is requested as an identity field in many processes: credit applications, insurance quotes and policies, public-benefit applications. The numbers exposed here were held by an auto insurer. Even without an image, the number itself works as an application field in the US.
Public agencies' own documents show how:
- In a February 2021 alert, the New York State Department of Financial Services (DFS) said stolen driver's license numbers had been used to submit fraudulent claims for pandemic and unemployment benefits, and that the effort seemed to coincide with stronger identity requirements for those benefits.
- The California DMV's fraud review form (INV 35) lists these types of identity fraud: financial/credit card fraud, misuse of a driver license number, DMV record, accident and ticket. Misuse of a license number can reach your driving record itself, not just your money.
What a credit freeze blocks
- Opening new credit cards and loans
- Contracts that involve pulling your credit file
- (Per the FTC, while a freeze is in place nobody, including you, can open a new credit account in your name)
What sits outside a freeze
- Public-benefit claims (the use DFS warned about)
- Your license record (an accident or ticket attached to the wrong person, for example)
- Processes that don't involve a credit check
This site's view: with a 'numbers only' leak, you need two front doors
For the Japanese Times Car breach, where licence images leaked, we recommended a fraud-alert registration with Japan's credit bureaus. Here it's numbers, not images, but because the number itself works as an application field in the US, you need two front doors: the money door (the three credit bureaus) and the license door (your state motor vehicle agency). Stop at the first and the uses that never touch your credit file, such as benefit claims and your driving record, stay out of view.
By contrast, in the Dutch Odido breach the authorities said a number alone can't open a loan or bank account. The same "licence numbers leaked" headline weighs differently depending on what the number unlocks in that country. That's what you see when you line the three cases up.
For anyone who stores identity numbers
The company hasn't disclosed which system the files came from or how they were taken. What follows is general guidance for anyone holding numbers that work on applications, like driver's license numbers. It is not a statement about the cause of this incident.
Don't send full numbers to the browser
The 2021 DFS alert followed cases in which full, unredacted driver's license numbers were stolen from auto insurers' instant online quote websites. DFS asked companies to review whether it is necessary to display any nonpublic information, even redacted, on public-facing websites, and not to display it without a compelling reason. Where display is needed, never send the full number to the browser. Masking it on screen means nothing if the full number is in the response data.
Shrink what one employee's credentials can reach
The company lists disabling compromised credentials and resetting passwords among its responses. In general, make sure one person's compromised credentials can't reach files covering millions of people: separate permissions by job, and put an extra approval or alert in front of bulk file access. See choosing multi-factor authentication and the minimum security baseline for organizations.
Be able to answer 'whose data is in here?' quickly
The company says identifying the affected people took about three months because of the nature and scope of the files. If you keep an inventory of which files hold which kinds of personal data, for how many people, you can shorten the time to notice after an incident. Data you don't hold can't leak, so set deletion deadlines for numbers you no longer need.
Sources (public record)
The facts in this article are based on the public information below. Undisclosed attack methods are not speculated on.
- AssuranceAmerica Managing General Agency, LLC, "Notice of Data Breach" (July 10, 2026) — app-privacy.assuranceamerica.com
- California Attorney General, "Submitted Breach Notification Sample: AssuranceAmerica Managing General Agency, LLC" (listed June 17, 2026) — oag.ca.gov
- Indiana Attorney General, "Data Breach Year to Date Report 2026" (6,998,886 affected; notices sent July 10, 2026) — in.gov
- Federal Trade Commission, "Identity Theft: A Recovery Plan" (steps when driver's license information is exposed) — consumer.ftc.gov
- FTC, "Credit Freezes and Fraud Alerts" — consumer.ftc.gov / Reporting: IdentityTheft.gov / Free credit reports: annualcreditreport.com
- USA.gov, "State motor vehicle services" (directory of state agencies) — usa.gov
- California DMV, "Fraud Review of Driver License/Identification Record (INV 35)" — dmv.ca.gov
- New York State Department of Financial Services, "Cyber Fraud Alert on Campaign to Steal Nonpublic Information (NPI)" (February 16, 2021) — dfs.ny.gov
Update history
2026-09-30: First version, based on AssuranceAmerica's July 10, 2026 notice, public filings with the California and Indiana attorneys general, and FTC, California DMV and NY DFS publications. We will update it if the company publishes more.
Read next
- The Japanese counterpart: The Times Car breach (driver's licence images leaked)
- Same pattern overseas: Odido (Netherlands: passport and licence numbers) / Quest Apartment Hotels (Australia: cards and passport numbers)
- Scams that follow a breach: What is phishing? / Choosing a password manager
- Other 2026 incidents: List of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat was exposed in the AssuranceAmerica breach?
According to the company's July 10, 2026 notice, the information in the affected files varies by individual and includes one or more of: name, contact information, automobile insurance policy or insurance account information, driver or vehicle information, claims-related information, and driver's license number. For a limited number of individuals, it also included Tax ID information or a Social Security number.
QHow many people were affected?
The Indiana Attorney General's 2026 data breach list shows 6,998,886 people affected in total for AssuranceAmerica Managing General Agency, LLC (237,141 of them Indiana residents), with notices sent on July 10, 2026.
QWhat caused it?
The company says it detected suspicious activity on certain systems on March 17, 2026, which appears to have resulted from malicious activity on March 16 that targeted one of its employees. Its investigation found that an unauthorized third party accessed certain portions of its IT environment and copied certain data files. The specific method has not been disclosed.
QIs credit monitoring offered?
The notice says the company is offering affected residents of California and Pennsylvania a complimentary 12-month credit monitoring service, with an enrollment deadline of October 10, 2026; residents interested in enrolling are asked to contact the company. The notice does not describe monitoring for residents of other states.
QWhat can someone do with my driver's license number?
In the US, a driver's license number serves as an identity field in many processes. In a February 2021 alert, the New York State Department of Financial Services (DFS) said stolen driver's license numbers had been used to submit fraudulent claims for pandemic and unemployment benefits. The California DMV's fraud review form lists financial/credit card fraud, misuse of a driver license number, DMV record, accident and ticket as types of identity fraud. AssuranceAmerica has not said that any misuse of the data from this incident has been found.
QMy driver's license number was exposed. What should I do?
The FTC's identity theft recovery guidance says to contact your nearest motor vehicles branch if your driver's license information was lost or stolen; the state might flag your license number in case someone else tries to use it, or suggest that you apply for a duplicate. Also check your credit reports at annualcreditreport.com and place a free credit freeze with all three nationwide credit bureaus.
QShould I trust calls or emails about my claim or policy?
Be cautious. The exposed data includes policy and claims information, which makes impersonation more convincing. Don't use phone numbers or links from an unexpected message; call the number on your policy documents or insurance ID card instead.